We are a 14-person architecture and project consulting firm based in Berlin. Our employees use their own smartphones to view drawings and reply to emails out in the field (BYOD). This morning our site manager called in a panic; he said that after clicking a parcel tracking link sent to his phone, unauthorized actions started running on the device, and his banking and email apps kept throwing security alerts back-to-back.
The device had our company email account, our cloud storage, and sensitive technical specifications for an ongoing public tender worth 180.000 EUR on it. The employee's personal photos and private data are on the same phone as well. Operationally and legally, what exact steps should we take in these first few hours? Is it the right call to wipe the device remotely, or should we secure the other accounts first?